Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Windows 11 File Explorer Speeds Up Large File Deletions
July 27, 2026
SparkKitty Malware Steals Crypto Seed Phrases From iOS and Android Photos
July 27, 2026
Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
July 27, 2026
Home/CyberSecurity News/BlueNoroff Hijacks Telegram Accounts to Deliver ClickFix Malware
CyberSecurity News

BlueNoroff Hijacks Telegram Accounts to Deliver ClickFix Malware

Key Takeaways North Korean threat actor BlueNoroff is hijacking legitimate Telegram accounts of industry contacts. The compromised accounts are used to target senior staff at cryptocurrency and Web3...

David kimber
David kimber
July 27, 2026 4 Min Read
2 0

Key Takeaways

  • North Korean threat actor BlueNoroff is hijacking legitimate Telegram accounts of industry contacts.
  • The compromised accounts are used to target senior staff at cryptocurrency and Web3 firms with fake Zoom and Microsoft Teams meeting links.
  • The campaign, dubbed ClickFix, aims to steal cryptocurrency and credentials by deploying sophisticated malware after profiling victims’ browsers for crypto wallets.
  • The attack chain involves social engineering, fake video calls, and a malicious “fix” that tricks users into executing harmful commands.
  • Organizations in the Web3 and crypto sectors must exercise extreme caution and verify meeting invitations through alternative communication channels.

BlueNoroff Leverages Compromised Telegram Accounts in Sophisticated ClickFix Campaign

A North Korean state-sponsored hacking collective, BlueNoroff, has significantly advanced its social engineering tactics, now exploiting trusted Telegram accounts to distribute malware. This group, an integral part of the larger Lazarus Group ecosystem, is actively compromising the Telegram profiles of legitimate industry professionals to launch targeted attacks.

Table Of Content

  • Key Takeaways
  • BlueNoroff Leverages Compromised Telegram Accounts in Sophisticated ClickFix Campaign
  • Exploiting Trust: The Blueprint of BlueNoroff’s Telegram Hijacks
  • What You Should Do

These hijacked accounts then send fraudulent invitations for Zoom and Microsoft Teams meetings to high-ranking personnel within cryptocurrency and Web3 organizations. The primary objective is financial gain, with operators systematically scanning victims’ browsers for cryptocurrency wallets before deploying their custom malware, ultimately seeking to exfiltrate credentials and digital assets to fund state operations.

This operation transcends typical phishing, functioning as a self-propagating pipeline that expands its reach with each new compromised contact. Security analysts at Jumpsec uncovered the intricate details of this campaign after identifying exposed JavaScript source maps on the attackers’ live infrastructure.

Jumpsec said in a report that the attacker’s toolkit effectively impersonates legitimate Zoom and Teams meeting interfaces while covertly profiling victims for cryptocurrency wallets and manipulating them into executing a malicious “ClickFix” command.

The research team successfully reconstructed both Windows and macOS attack paths, from the initial lure to the final stages of data exfiltration. A critical element of this campaign is its reliance on established trust; victims receive malicious links from individuals they know and may have previously interacted with in person. This renders conventional advice to “check the sender” ineffective, as the account itself is genuine, only its controller has changed. This pattern mirrors other recent BlueNoroff campaigns that have employed fake meeting pages to target cryptocurrency professionals.

The impact of a successful compromise extends broadly. Any infected machine with an active Telegram session risks having its session hijacked, perpetuating a cycle that continuously ensnares new targets. Firms managing substantial digital assets remain prime targets, as a single successful breach can yield significant illicit gains.

Exploiting Trust: The Blueprint of BlueNoroff’s Telegram Hijacks

In cases analyzed by Jumpsec, compromised Telegram accounts belonging to real contacts were used to message senior employees at prominent companies. These interactions often begin with what appears to be an ordinary meeting invitation. The malicious links are carefully crafted, incorporating familiar labels like “us.zoom” into attacker-controlled domains, creating a deceptive sense of security.

Upon clicking the link, victims are prompted to enter a name and grant camera access. Unbeknownst to them, their webcam feed is silently transmitted to the operator’s control panel. Victims are then placed in a simulated waiting room, while the attacker joins the “meeting” with a staged video, often constructed from AI-generated headshots combined with real body motion to enhance credibility.

During the fake call, timed chat messages falsely claim microphone issues and prompt the victim to install a bogus Zoom SDK update. This leads to the “ClickFix” prompt, where the victim is instructed to copy what appears to be a simple fix. However, the clipboard content is surreptitiously replaced with a harmful command. This social engineering technique builds upon the broader ClickFix lure strategy observed in other malware campaigns.

Crucially, before any payload is delivered, the attack kit meticulously scans the victim’s browser for cryptocurrency wallet extensions, such as MetaMask, and related digital asset objects. These reconnaissance results are sent to the operator panel, ensuring that only high-value targets proceed through the full attack chain. While the Zoom and Teams builds share a common core module, the presence of a Google Meet string in the code suggests the potential existence of a third lure. This persistent focus on decentralized finance (DeFi) trust and chat-based delivery is a recurring theme in Lazarus Group’s cryptocurrency-focused operations.

What You Should Do

  • Verify All Meeting Invitations: If you receive a Zoom, Teams, or Google Meet invitation via Telegram, especially from someone you know, independently verify the meeting details through a separate communication channel (e.g., a phone call, email to a known address, or an alternative messaging app). Do not rely solely on the Telegram message.
  • Scrutinize URLs: Always examine the full domain of any link before clicking. Do not be fooled by legitimate-sounding subdomains (e.g., “us.zoom”) if the main domain is unfamiliar or suspicious. Real meeting tools will never ask you to paste terminal commands to resolve audio or camera issues.
  • Be Wary of Unexpected Requests: Be highly suspicious of any requests to download “updates,” “SDKs,” or execute commands from your clipboard, particularly during a meeting setup or troubleshooting.
  • Implement Multi-Factor Authentication (MFA): Enable MFA on all your online accounts, especially for Telegram, cryptocurrency exchanges, and corporate services, to add an extra layer of security against account hijacking.
  • Educate Employees: Conduct regular cybersecurity awareness training, emphasizing the sophisticated social engineering tactics employed by groups like BlueNoroff, particularly for employees in high-value roles or those handling digital assets.
  • Monitor for Indicators of Compromise (IoCs): Security teams should actively monitor their networks for the provided IoCs (SHA256 hashes, domains, and IP addresses) and block them at the perimeter.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Researchers Boot Jailbroken iOS 17 on iPhone 11 Pro

Next Post

PyPI Blocks New File Uploads on Old Releases to Prevent Package Poisoning

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Researchers Boot Jailbroken iOS 17 on iPhone 11 Pro
July 27, 2026
Google Names Cybercrime Groups to Detail Motives and Origins
July 27, 2026
Critical ChatGPT AgentForger Flaw Lets Attackers Deploy Rogue Agents
July 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us